Medium severity6.5NVD Advisory· Published Aug 6, 2021· Updated Jun 17, 2026
CVE-2021-38136
CVE-2021-38136
Description
Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:corero:securewatch_managed_services:9.7.2.0020:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:corero:securewatch_managed_services:9.7.2.0020:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 9.7.2.0020
Patches
Vulnerability mechanics
References
2- www.shielder.it/advisories/corero_secure_watch_managed_services-get_snapshot-path-traversal/nvdExploitThird Party Advisory
- www.corero.com/blog/data-sheets-corero-securewatch-managed-services/nvdProduct
News mentions
0No linked articles in our index yet.